awsclaw-lambda
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides the
Invokecommand, which allows the agent to execute code within AWS Lambda functions as part of its management capabilities. - [DATA_EXFILTRATION]: Commands such as
GetFunctionConfigurationandGetPolicyallow the agent to read function metadata, environment variables, and resource-based policies, which may contain sensitive configuration details or secrets. - [EXTERNAL_DOWNLOADS]: The
CreateFunctionandUpdateFunctionCodecommands facilitate the retrieval of deployment packages and function code from S3 buckets or container images in ECR.
Audit Metadata